---
id: CVE-2026-54371
title: >-
  attr before version 2.6.0 contains a symlink traversal vulnerability in the
  getfattr and setfattr utilities that allows local attackers to escalate
  privileges by replacing a pathname component with a symbolic link during
  directory hierar…
summary: >-
  attr before version 2.6.0 contains a symlink traversal vulnerability in the
  getfattr and setfattr utilities that allows local attackers to escalate
  privileges by replacing a pathname component with a symbolic link during
  directory hierar…
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-59
vendor: attr project
product: attr
affected:
  - attr < 2.6.0
patched:
  - enterprise_linux_appstream_v_10
  - enterprise_linux_appstream_v_9
  - enterprise_linux_baseos_v_10
  - enterprise_linux_baseos_v_8
  - enterprise_linux_baseos_v_9
  - cert_manager_support_for_red_hat_openshift_release 1.19
  - discovery 2
  - hardened_images
published: '2026-06-29'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T13:18:15.587'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54371'
references:
  - url: >-
      https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=49f79e947270f06940b9100fa638f85dddc4aa7f
    label: disclosure@vulncheck.com
  - url: >-
      https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=c440855d6b33446edf4b5eb1a2d892281f15a99b
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/attr-symlink-traversal-privilege-escalation-via-getfattr-setfattr
    label: disclosure@vulncheck.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:34889'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:56133'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:59380'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:60226'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:61783'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:63135'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:63138'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/errata/RHSA-2026:66018'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://access.redhat.com/security/cve/CVE-2026-54371'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2490283'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-54371'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-54371'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-30T14:41:00.558077Z'
epss: 0.00179
epssPercentile: 0.06667
scores:
  nvd: 7.1
  vendor: 6.3
  cna: 7.1
ingestedAt: '2026-07-03T20:53:53.285Z'
---

## Overview

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2026:59380** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux BaseOS (v. 10) · released 2026-08-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:59380)
- **RHSA-2026:60226** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux BaseOS (v. 9) · released 2026-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2026:60226)
- **RHSA-2026:56133** · Red Hat · fixed in: Red Hat Enterprise Linux BaseOS (v. 8) · released 2026-08-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:56133)
- **RHSA-2026:63135** · Red Hat · fixed in: Cert Manager support for Red Hat OpenShift release 1.19 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63135)
- **RHSA-2026:63138** · Red Hat · fixed in: Cert Manager support for Red Hat OpenShift release 1.19 · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63138)
- **RHSA-2026:61783** · Red Hat · fixed in: Red Hat Discovery 2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61783)
- **RHSA-2026:34889** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:34889)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat OpenShift Container Platform 4 · updated 2026-09-10 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54371.json)
- **RHSA-2026:66018** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:66018)
